SOC 2 · CC7

CC7 · System Operations

5 controls in this family.

detectivehigh
Adopt

Vulnerability Management Program

Continuous scanning of production infrastructure and applications for known vulnerabilities, with SLA-based remediation.

CC7.1

Testing: Weekly

detectivehigh
Adopt

Annual Penetration Testing

Annual external penetration test of production infrastructure and applications by an independent third party.

CC7.1

Testing: Annually

detectivehigh
Adopt

Security Monitoring and SIEM

Centralized log aggregation and automated alerting for security-relevant events across production systems.

CC7.2

Testing: Daily

correctivehigh
Adopt

Security Incident Response Plan

Documented and tested plan for detecting, containing, eradicating, and recovering from security incidents.

CC7.3CC7.4

Testing: Semi-annually

correctivemedium
Adopt

Post-Incident Review Process

Blameless post-mortems after security incidents to identify root causes, contributing factors, and preventive actions.

CC7.4CC7.5

Testing: Per incident